CVE-2026-19282Disclosure

LOWCVSS 1.9 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A weakness has been identified in andreahaku llm_memory_mcp up to f11dc8bcff3ff8cf943a2945f99ff3b0bdc8a6d0. This impacts the function auto.capture of the file src/autolearn/GitHooksManager.ts of the component llm_memory_mcp. Executing a manipulation of the argument hash can lead to command injection. The attack is restricted to local execution. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-77

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-08: 3Technical Details · 2026-08-08: 308-08
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • CyberSignal | Cybersecurity News@XQOPTRX
    Disclosure

    🤖 Another MCP project hit by command injection CVE-2026-19282 affects the llm_memory_mcp project. Manipulation of a hash argument in its Git hooks functionality can lead to command injection. The issue requires local execution and was published August 8. 🔎 Source: http://CVE.org / NVD / VulDB. #MCP #LLMSecurity #AISecurity #CVE #CyberSecurity

    Post summary

    The post announces CVE-2026-19282, a command injection flaw in llm_memory_mcp’s Git hooks that requires local execution, but does not provide a PoC, exploit code, patches, or evidence of active exploitation.

    0000040
    34 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-19282 A weakness has been identified in andreahaku llm_memory_mcp up to f11dc8bcff3ff8cf943a2945f99ff3b0bdc8a6d0. This impacts the function auto.capture of the file src/aut… https://www.cve.org/CVERecord?id=CVE-2026-19282 ----- Traducción: CVE-2026-19282 Se … http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-19282, detailing a weakness in the auto.capture function of andreahaku llm_memory_mcp, linking to the CVE record but providing no PoC, exploit, patch, or active exploitation information.

    0000031
    98 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-19282 A weakness has been identified in andreahaku llm_memory_mcp up to f11dc8bcff3ff8cf943a2945f99ff3b0bdc8a6d0. This impacts the function auto.capture of the file src/aut… https://www.cve.org/CVERecord?id=CVE-2026-19282

    Post summary

    The statement announces a weakness in the `andreahaku llm_memory_mcp` code base, specifically affecting the `auto.capture` function, but provides no evidence of exploitation, mitigation, or PoC.

    00000951
    57.9K followersView on X

Explore more